CVE-2026-61500: Rejetto HFS Session Cookie Key Derived from Math.random()
ID: 31c7d807-6faa-55d8-b5bc-85f843acc9e4
STIX ID: report--31c7d807-6faa-55d8-b5bc-85f843acc9e4
Feed Name: CosmicBytez Labs
Threat Score
This advisory details CVE-2026-61500: HFS 3.0.0–3.2.0 generates session-cookie signing keys using Math.random() and leaks PRNG outputs in login responses, enabling attackers to reconstruct the PRNG state, recover the signing key, and forge admin session cookies to obtain full unauthenticated access and exfiltrate or modify hosted files; the report provides technical analysis, attack steps, impact, and remediation/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
